Use-After-Free Vulnerability in Envoy Proxy by Envoy Project
CVE-2026-47207
6.5MEDIUM
What is CVE-2026-47207?
Envoy Proxy, an open-source edge and service proxy for cloud-native applications, is vulnerable to a use-after-free error caused by improperly crafted gRPC messages sent from an ext_proc server. Specifically, if the first response in a batch results in the destruction of the gRPC stream object, Envoy may fail when processing subsequent ProcessingResponse messages. This issue affects specific versions of Envoy Proxy, and remediation steps have been provided in the latest security updates.
Affected Version(s)
envoy >= 1.38.0, < 1.38.3 < 1.38.0, 1.38.3
envoy >= 1.37.0, < 1.37.5 < 1.37.0, 1.37.5
envoy >= 1.36.0, < 1.36.9 < 1.36.0, 1.36.9
